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Disposition of Claims 
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DETAILED ACTION 

1 . This Office action is in response to the amendment filed on January 17, 2006. 

2. Claims 1 -7, 1 3-1 6. 1 8-20, 22, 26-30, 36, 39-47, 49, 50 and 52-60 are pending. 

3. Claims 1 , 22, 26, 36, 39 and 47 are amended. 

4. Claims 8-12, 17, 21 , 23-25, 31-35, 37, 38, 48 and 51 are canceled. 

5. Claims 55-60 are new. 

6. The text of those sections of Title 35, U.S. Code not included in this action can 
be found in a prior Office action. 

Response to Amendment 

7. The 1 1 2/1 ^' paragraph rejections to claims 1 -7, 1 3-1 6, 1 8-20, 22, 26-30, 36, 39- 
47, 49, 50 and 52-54 are withdrawn as the amendment to the claims overcome the 

1 12/1®* paragraph rejection. However, in light of the amended claims, in particular the 
new limitation wherein the antivirus scans a segment without using file-based 
information, claims 1-7, 13-16, 18-20, 22, 36, 47, 49, 50, 52 and 53 are rejected as 
being unpatentable over Wells in view of Frisch, Kim and Ko USPN 6,697,950 as 
outlined below. Claims 26-30, 39-46 and 55-60 are allowed, and claim 54 is objected to 
as being dependent upon a rejected base claim. 
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Claim Rejections - 35 USC § 103 

8. Claims 1-7, 13-16, 18-20, 22, 36, 47, 49, 50, 52 and 53 are rejected under 35 
U.S.C. 103(a) as being unpatentable over Wells U.S. Patent No. 6,338,141 (hereinafter 
Wells) in view of Frisch Essential Svstem Administration (hereinafter Frisch), Kim "The 
Design and Implementation of Tripwire: A File System Integrity Checker" (hereinafter 
Kim) and Ko USPN 6,697,950. (hereinafter Ko) 

9. As per claim 1 , Wells discloses a method of detecting computer viruses on a 
single, stand-alone computer system or on a networked machine using an antivirus unit, 
wherein a user of the antivirus unit designates a set of files on a system to be scanned 
(see Wells, abstract; col. 9:1-4). Wells does not expressly disclose providing a disk 
space having at least a portion that is partitioned into separate segments, each segment 
being accessed by at least one of a plurality of hosts, wherein a first one of the 
segments is accessed using a different file system than a second one of the segments. 
However, this configuration is found in networked operating systems. For example, 
Frisch teaches a UNIX operating system that enables a flexible partitioning capability 
wherein each partitioned segment is accessed using a different file system, (pgs. 409- 
414 'From Disks to Filesystems', especially pg. 409, first paragraph in the section) 
Moreover, Frisch discloses exporting local filesystems by a particular system for 
network access by other hosts to mount to their system, (pgs. 612-614 'Exporting Local 
Filesystems") Hence, it would be obvious to one of ordinary skill in the art at the time the 
invention was made for the method of detecting a virus to be actuated on a disk space 
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having at least a portion that is partitioned into separate segments, each segment being 
accessed by at least one of a plurality of hosts, wherein a first one of the segments is 
accessed using a different file system than a second one of the segments, since it 
enables an administrator broader control to allow or restrict access to information on a 
disk by segmenting the disk on a partition level as taught by Frisch. (page 394, 2"^ and 
3^*^ paragraphs) 

10. Further, Wells does not expressly disclose scanning for a virus on a portion of 
the disk that includes a part of the first and second segments. However, means of 
selectively checking the integrity of separate filesystems on a disk is a feature of the 
UNIX tool Tripwire. Kim teaches how different filesystems on a disk can be checked by 
entering the paths of relevant filesystems as well as corresponding selection-masks, 
which classifies how to observe changes in the filesystem, in the Tripwire configuration 
file, (page 1 1 , Figure 2 and related text) Furthermore, Kim teaches Tripwire as a 
function operating in a larger security methodology: the results of a Tripwire check can 
be used by a filter program, (page 12, 2"^ paragraph, 'quiet option') It would be obvious 
to one of ordinary skill in the art at the time the invention was made to selectively scan 
separate filesystems on a disk space for viruses since it enables the method to secure 
any suspicious subset of data on a disk, even across partitioned boundaries. 

1 1 . Moreover, the invention of Wells scans all types of files and does not limit 
scanning to only non-native files (Wells, 2:15-20); also file sharing between different 
operation systems is a common feature among networked systems. As taught by 
Frisch in a different chapter, non-native files are transferred between a UNIX system 
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and any reachable system (non-local and/or non-UNIX) using commands "ftp" and 
"telnet", (pg. 587, 4*^ and 5*^ bullets) Non-native files downloaded from non-local or non- 
UNIX platforms are incorporated into the local filesystem, and likewise are a portion of 
the disk space to be scanned. It would be obvious to one of ordinary skill in the art at 
the time the invention was made for the antivirus unit, using a particular operating 
system, to access non-native files created using operating systems different from the 
particular operating system that is used by the antivirus unit in connection with scanning 
at least parts of the disk space for viruses since file sharing between platforms is a 
common technique as known to one of ordinary skill in the art and as taught by Frisch, 
ibid. 

12, Finally, Wells does not disclose the antivirus unit scans at least one of the 
segments without using file-based information of the particular operating system or of 
any host having access to the at least one segment. However, Ko discloses several 
techniques of scanning for viruses without using file-based information of the particular 
operating system or of any host having access to the at least one segment. Ko teaches 
it is common to use virus scanners to perform pattern matching on code to determine 
whether a known virus is present in the code, since this technique is simple and has a 
low false alarm rate. (col. 1:65-2:3) Ko also discloses a method and apparatus for 
detecting macro computer virus using static analysis, wherein macro operations within a 
document are located and compared to suspected macro operations against a profile, 
which enables detection of new macro computer viruses. (2:27-46) Neither of these 
techniques use file-based information to scan for viruses. Therefore, it would be 
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obvious to one of ordinary skill in the art at the time the invention was made to combine 
the method of detecting a virus as taught by Ko with the method of scanning a 
filesystem to detect viruses as taught by Wells such that the antivirus scans without 
using file-based information of the particular operating system or of any host having 
access to the at least one segment. One would be motivated to do so since the 
technique of scanning by pattern matching is a simple but yet fail safe means of 
detecting known viruses, and the technique of detecting macro viruses using static 
analysis enables the detection of previously unknown viruses as taught by Ko, ibid. The 
aforementioned cover the limitations of claim 1 . 

13. As per claim 2, the rejection of claim 1 under 35 U.S.C. 103(a) is incorporated 
herein, (supra) In addition, the first and second segments correspond to different 
physical portions of the disk space. (Frisch, pg. 410, Figure 9-3) 

14. As per claim 3, the rejection of claim 2 under 35 U.S.C. 103(a) is incorporated 
herein, (supra) In addition, Frisch teaches an embodiment of the UNIX OS wherein the 
first and second segments overlap, (pgs. 39-41, "Links") It would be obvious to one of 
ordinary skill in the art at the time the invention was made for the first and second 
segments to overlap to enable information pertinent to multiple segments to be shared 
between the segments as taught by Frisch, ibid. The aforementioned cover the 
limitations of claim 3. 
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15. As per claim 4, the rejection of claim 2 under 35 U.S.C. 103(a) is incorporated 
herein, (supra) In addition, Frisch teaches an embodiment of the UNIX OS wherein the 
first and second segments do not overlap, (pg. 395, Figure 9-1 , disk 1 ) It would be 
obvious to one of ordinary skill in the art at the time the invention was made for the first 
and second segments to not overlap to organize segments into distinct logical partitions 
as taught by Frisch. Ibid. The aforementioned cover the limitations of claim 4. 

16. As per claim 5, the rejection of claim 1 under 35 U.S.C. 103(a) is incorporated 
herein, (supra) In addition, Frisch teaches an embodiment of the UNIX OS wherein 
the first and second segments correspond to logical entities, (pg. 395, Figure 9-1 , disk 
1 ) It would be obvious to one of ordinary skill in the art at the time the invention was 
made for the first and second segment to correspond to logical entities since it enables 
a direct correlation between a physical partition and a logical partition as taught by 
Frisch, ibid. The aforementioned cover the limitations of claim 5. 

17. As per claim 6, the rejection of claim 5 under 35 U.S.C. 103(a) is incorporated 
herein, (supra) In addition, Frisch teaches an embodiment of the UNIX OS wherein the 
first and second segments overlap, (pgs. 39-41, "Links") It would be obvious to one of 
ordinary skill in the art at the time the invention was made for the first and second 
segments to overlap to enable information pertinent to multiple segments to be shared 
between the segments as taught by Frisch, ibid. The aforementioned cover the 
limitations of claim 6. 
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18. As per claim 7, the rejection of claim 5 under 35 U.S.C. 103(a) is incorporated 
herein, (supra) In addition, Frisch teaches an embodiment of the UNIX OS wherein the 
first and second segments do not overlap, (page 395, Figure 9-1, disk 1) It would be 
obvious to one of ordinary skill in the art at the time the invention was made for the first 
and second segments to not overlap to organize segments into distinct logical partitions 
as taught by Frisch, ibid. The aforementioned cover the limitations of claim 7. 

19. As per claim 13, the rejection of claim 1 under 35 U.S.C. 103(a) is incorporated 
herein, (supra) In addition, Kim teaches implementing at least part of Tripwire using 
stand-alone hardware. (Kim, page 12, section 4.3.1) It would be obvious to one of 
ordinary skill in the art at the time the invention was made to implement at least part of 
the antivirus unit using stand-alone hardware to ensure the inviolability of the integrity 
database used by Tripwire (Kim, page 12, section 4.3,1, first paragraph in the section, 
2"^ sentence) The aforementioned cover the limitations of claim 13. 

20. As per claim 14, the rejection of claim 1 under 35 U.S.C. 103(a) is incorporated 
herein, (supra) In addition, Frisch and Kim teach implementing at least part of the 
antivirus unit as a process running on at least one of the hosts (Frisch, page 43, 
'Processes'; Kim, page 10, section 4.1.2, 'Scalability' and section 4.1.3, 'Configurability 
and flexibility'; Wells, col. 3, lines 10-11) It would be obvious to one of ordinary skill in 
the art at the time the invention was made for a part of the antivirus unit be a process 
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running on at least one of the hosts since any application run on a machine comprises 
at least one process on the machine: as defined by Frisch, a process is a single 
program running in its own virtual address space, (page 43, last paragraph, first 
sentence) The aforementioned cover the limitations of claim 14. 

21. As per claim 15, the rejection of claim 1 under 35 U.S.C. 103(a) is incorporated 
herein, (supra) In addition, Frisch teaches the useable areas of a disk space are 
partitioned into separate segments in any given partitioned disk, (page 395, Figure 9-1, 
disk 1; page 410, Figure 9-3) It would be obvious to one of ordinary skill in the art at the 
time the invention was made for the useable areas of the disk space to be partitioned 
into separate segments to enable each disk partition to be usable to a user or 
application. The aforementioned cover the limitations of claim 15. 

22. As per claim 16, the rejection of claim 1 under 35 U.S.C. 103(a) is incorporated 
herein, (supra) In addition. Wells and Kim teach the antivirus unit scans useable areas 
of the disk space. (Kim, page 1 1 , Figure 2; Wells, col. 1 , lines 54-60) It would be 
obvious to one of ordinary skill in the art at the time the invention was made for the 
antivirus unit to scan useable areas of the disk space since these areas are workspaces 
having read/write privileges for users and applications and are prone to integrity attacks 
when a virus attains these privileges. The aforementioned cover the limitations of claim 
16. 
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23. As per claim 18, the rejection of claim 1 under 35 U.S.C. 103(a) is incorporated 
herein, (supra) In addition, Frisch teaches an embodiment of the UNIX OS wherein a 
particular segment assigned to a first host is inaccessible to other hosts, (page 29, 
Table 2-3, 'no access'; page 30, 5^^ line 'Other Access' and Figure 2-1; pages 228-229 
'Using Groups Effectively', especially page 228, 4*^ paragraph, second sentence) It 
would be obvious to one of ordinary skill in the art at the time the invention was made 
for a particular segment assigned to a first host to be inaccessible to other hosts for the 
purpose of enforcing non-use of those who do not require access to a segment. (Frisch, 
page 228, 4^*^ paragraph, second sentence) The aforementioned cover the limitations of 
claim 18. 

24. As per claim 19, the rejection of claim 18 under 35 U.S.C. 103(a) is incorporated 
herein, (supra) In addition, Frisch teaches an embodiment of the UNIX OS wherein all 
of the segments are at least readable by the antivirus unit, (page 29, Table 2-3, 'read 
access only'; page 30, 3''^ line 'Group access' and Figure 2-1 ; pages 228-229 'Using 
Groups Effectively', especially page 228, 3''^ paragraph, first sentence and 4*^ 
paragraph, last sentence) It would be obvious to one of ordinary skill in the art at the 
time the invention was made for all of the segments to be readable by the antivirus unit 
to enable the antivirus unit to comprehensively check the integrity of the disk. (Frisch, 
page 228, 3^^ paragraph, first sentence and 4*^ paragraph) The aforementioned cover 
the limitations of claim 19. 
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25. As per claim 20, the rejection of claim 1 under 35 U.S.C. 103(a) is incorporated 
herein, (supra) In addition, Kim and Frisch teach that at least a portion of the antivirus 
unit is provided on at least some controllers for disks corresponding to the disk space. 
(Kim, page 1 1 , Figure 2, first entry Veto' and Section 4.2; Frisch, pages 398-405, The 
Filesystem Configuration File', especially page 398, 7etc/fstab') It would be obvious to 
one of ordinary skill in the art at the time the invention was made for a portion of the 
antivirus unit to be provided on at least some controllers for disks corresponding to the 
disk space to enable a comprehensive integrity check methodology. The 
aforementioned cover the limitations of claim 20. 

26. As per claim 22, the rejection of claims 1-8, 13-16 and 18-20 under 35 U.S.C. 
103(a) is incorporated herein, (supra) In addition, Kim teaches a first scan at a first 
time and a second scan at a second time after the first time, wherein the results of the 
first scan are taken into consideration in the performing of the second scan as outlined 
in the invention covered in the claim 1-8, 13-16 and 18-20 rejections, (page 14, section 
4.5) It would be obvious to one of ordinary skill in the art at the time the invention was 
made for there to be a first virus scan at a first time and a second virus scan at a 
second time after the first time and dependent on the results of the first scan since the 
scans are automated on a periodic basis and the integrity of the segments must be 
accounted for consistent with preceding scans starting with the inception of the checks 
to ensure integrity is maintained over the course of multiple periods. (Kim, page 14, 
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section 4.5, 1^* paragraph of the section, 3''*^ sentence) The aforementioned cover the 
limitations of claims 22. 

27. As per claim 36, it is an apparatus claim corresponding to claim 22 and it does 
not teach or define above the information claimed in claim 22. Therefore, claim 36 is 
rejected as being unpatentable over Wells in view of Frisch, Kim and Ko for the same 
reasons set forth in the rejection of claim 22. 

28. As per claims 47, 49 and 50, they are apparatus claims corresponding to claims 
13, 20 and 22, and they do not teach or define above the information claimed in claims 
13, 20 and 22. Therefore, claims 47, 49 and 50 are rejected as being unpatentable over 
Wells in view of Frisch, Kim and Ko for the same reasons set forth in the rejections of 
claims 13, 20 and 22. 

29. As per claims 52 and 53, the rejections of claim 1 under 35 USC 103(a) Is 
incorporated herein, (supra) Neither Wells, nor Frisch, nor Kim, nor Ko disclose 
sharing access or restricting access to a segment with a first host when the antivirus 
unit is scanning the segment. However, it is notoriously well known in the art to choose 
between shared access or restricted access within a filesystem to promote singular 
access to those files where concurrent access is not desirable. For example, UNIX 
implements NT type file locks using Samba. Examiner takes Official Notice of this 
teaching. It would be obvious to one of ordinary skill in the art at the time the invention 
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was made to share access or restrict access to a segment with a first host when the 
antivirus unit is scanning the segment. One would be motivated to do so as this 
provides the system flexibility to allow concurrent access to certain files for ease of 
access and restricted access to prevent concurrent changes as known to one of 
ordinary skill in the art. 

Allowable Subject Matter 

30. Claims 26-30, 39-46 and 55-60 are allowed. 

31 . Claim 54 is objected to as being dependent upon a rejected base claim, but 
would be allowable if rewritten in independent form including all of the limitations of the 
base claim and any intervening claims. 

Conclusion 

32. Applicant's amendment necessitated the new ground(s) of rejection presented in 
this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP 

§ 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 
CFR 1.136(a). 

A shortened statutory period for reply to this final action is set to expire THREE 
MONTHS from the mailing date of this action. In the event a first reply is filed within 
TWO MONTHS of the mailing date of this final action and the advisory action is not 
mailed until after the end of the THREE-MONTH shortened statutory period, then the 
shortened statutory period will expire on the date the advisory action is mailed, and any 
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extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of 
the advisory action. In no event, however, will the statutory period for reply expire later 
than SIX MONTHS from the date of this final action. 

Communications Inquiry 

Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Jung W. Kim whose telephone number is 571-272-3804. 
The examiner can normally be reached on M-F 9:00-5:00. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Gilberto Barron can be reached on 571-272-3799. The fax phone number 
for the organization where this application or proceeding is assigned is 571-273-8300. 

Information regarding the status of an application may be obtained from the 
Patent Application Information Retrieval (PAIR) system. Status information for 
published applications may be obtained from either Private PAIR or Public PAIR. 
Status information for unpublished applications is available through Private PAIR only. 
For more information about the PAIR system, see http://pair-direct.uspto.gov. Should 
you have questions on access to the Private PAIR system, contact the Electronic 
Business Center (EBC) at 866-217-9197 (toll-free). 

Jung W Kim 
Examiner 
Art Unit 2132 
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